CVE-2017-17718
published 2017-12-17CVE-2017-17718: The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.
PriorityP427medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.35%
68.8th percentile
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-net-ldap | < ruby-net-ldap 0.16.1-1 (bookworm) | ruby-net-ldap 0.16.1-1 (bookworm) |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | — | — |
| net-ldap_project | net-ldap | >= 0 < 0.16.0 | 0.16.0 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
net-ldap Improper Certificate Validation vulnerability
ghsa·2018-01-06
CVE-2017-17718 [MEDIUM] CWE-295 net-ldap Improper Certificate Validation vulnerability
net-ldap Improper Certificate Validation vulnerability
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.
OSV
net-ldap Improper Certificate Validation vulnerability
osv·2018-01-06
CVE-2017-17718 [MEDIUM] net-ldap Improper Certificate Validation vulnerability
net-ldap Improper Certificate Validation vulnerability
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.
OSV
CVE-2017-17718: The Net::LDAP (aka net-ldap) gem before 0
osv·2017-12-17·CVSS 5.9
CVE-2017-17718 [MEDIUM] CVE-2017-17718: The Net::LDAP (aka net-ldap) gem before 0
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.
Debian
CVE-2017-17718: ruby-net-ldap - The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certific...
vendor_debian·2017·CVSS 5.9
CVE-2017-17718 [MEDIUM] CVE-2017-17718: ruby-net-ldap - The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certific...
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.
Scope: local
bookworm: resolved (fixed in 0.16.1-1)
bullseye: resolved (fixed in 0.16.1-1)
forky: resolved (fixed in 0.16.1-1)
sid: resolved (fixed in 0.16.1-1)
trixie: resolved (fixed in 0.16.1-1)
Red Hat
rubygem-net-ldap: Missing SSL Certificate Validation
vendor_redhat·2016-01-14·CVSS 5.9
CVE-2017-17718 [MEDIUM] CWE-295 rubygem-net-ldap: Missing SSL Certificate Validation
rubygem-net-ldap: Missing SSL Certificate Validation
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.
Statement: This issue affects the versions of rubygem-net-ldap as shipped with Red Hat Subscription Asset Manager 1 and Satellite version 6. Red Hat Product Security has rated this issue as having Moderate security impact. No update is planned at this time however a future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: ruby193-rubygem-net-ldap (Red Hat Ceph Storage 1.3) - Will not fix
Package: ruby193-rubygem-net-ldap (Red Hat Subscription Asset Manager) - Will not fix
No detection rules found.
No public exploits indexed.
http://openwall.com/lists/oss-security/2017/12/17/10https://github.com/ruby-ldap/ruby-net-ldap/issues/258https://github.com/ruby-ldap/ruby-net-ldap/pull/279http://openwall.com/lists/oss-security/2017/12/17/10https://github.com/ruby-ldap/ruby-net-ldap/issues/258https://github.com/ruby-ldap/ruby-net-ldap/pull/279
2017-12-17
Published